{"id":"CVE-2020-1757","aliases":["GHSA-2w73-fqqj-c92p"],"url":"https://o3.security/vulnerability/CVE-2020-1757","summary":"Improper Input Validation in Undertow","details":"A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.","published":"2020-04-21T17:15:12.957Z","modified":"2026-07-08T05:53:40.809997772Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.undertow:undertow-core","fixedVersion":"2.1.0"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1757"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:53:40.809997772Z"}}